August 26-28, 2026
MAISON GLAD, Jeju Island, Korea

Invited Talks



 


 Invited Talk 1: Yan Shoshitaishvili (Professor, Arizona State University)
 Title: Vulnerability Shapes, and Their Implications
 Date : August 26 (Wed)

 


Abstract:

 Over the last few decades, researchers have uncovered thousands of vulnerabilities in targets ranging from IoT devices to web browsers, kernels, and bootloaders by using hundreds of different tools, techniques, and paradigms. Throughout it all, each successive tool somehow kept finding bugs in the same researched code-bases. Now, agentic vulnerability research is yet another new paradigm, once again finding new fascinating bugs in software that we really thought had finally been well-researched. Why does this keep happening? Through the lens of my journey in this space, I will explore the scientific underpinnings of what our community has long treated as an art form. I'll dig in to what vulnerabilities are, why we keep finding them, why the AI has revolutionized the space, and where we might go from here.


Biography:

 

 Yan Shoshitaishvili is an Associate Professor at Arizona State University, where he pursues parallel passions of cybersecurity research, real-world impact, and education. His research focuses on automated program analysis and vulnerability detection techniques. Aside from publishing dozens of research papers in top academic venues, Yan led Shellphish's participation in the DARPA Cyber Grand Challenge, achieving the creation of a fully autonomous hacking system that won third place in the competition, and helps guide Shellphish toward the final event of the successor competition, the AI Cyber Challenge.

 Underpinning much of his research is angr, the open-source program analysis framework created by Yan and his collaborators. This framework has powered hundreds of research papers, helped find thousands of security bugs, and continues to be used in research labs and companies around the world.

 When he is not doing research, Yan participates in the enthusiast, educational, and policy cybersecurity communities. He is a Captain Emeritus of Shellphish, one of the oldest ethical hacking groups in the world, and a founder of the Order of the Overflow, with whom he ran DEF CON CTF, the "world championship" of cybersecurity competitions, from 2018 through 2021. In order to inspire students to pursue cybersecurity (and, ultimately, compete at DEF CON!), Yan created pwn.college, an open practice-makes-perfect learning platform that is revolutionizing cybersecurity education for aspiring hackers around the world. He continues to develop novel approaches to cybersecurity workforce development in his role as Director of the American Cybersecurity Education Institute and has helped advise government policy through CISA's Technical Advisory Council.

 

 

 


Invited Talk 2: Ruoyu (Fish) Wang (Professor, Arizona State University)

Title: Goal-driven Binary Decompilation: A 10,000-feet View with Periodic Free Falls and Some Deep Dives”           
Date : August 26 (Wed)

 

Abstract:

 Decompilation---the art of turning stripped, optimized binaries back into code a human can read---sits at the heart of nearly every serious attempt to understand software we don't have the source for, from IoT firmware to browsers, kernels, and malware. Over the last few decades, we've built decompiler after decompiler, each one "better" than the last, and yet every reverse engineer still ends up fighting the output, silently rewriting it in their head toward whatever they actually came to do. Why does no decompiler ever feel done? Through the lens of my own journey building these tools and staring at what they produce, I'll argue that what our community has long treated as an art form is really a science we keep avoiding: there is no single correct decompilation, only decompilation for a goal. I'll dig into what decompilation actually is (and why it is fundamentally lossy), why one-size-fits-all output is a myth, why AI has suddenly made goal-driven decompilation possible, and where we might steer it from here. Expect a 10,000-feet view, a few free falls into the messy reality, and some deep dives into the code.

 

Biography:
 

 Ruoyu (Fish) Wang is an Associate Professor at Arizona State University, where he pursues parallel passions of cybersecurity research, real-world impact, and education. His research focuses on system security, with an emphasis on automated binary program analysis, reverse engineering, and decompilation---the recovery of accurate, human-readable source code from compiled binaries. Aside from publishing dozens of research papers at top academic venues, Fish is a core member of Shellphish, the hacker collective whose fully autonomous system Mechanical Phish took third place in the DARPA Cyber Grand Challenge, and whose LLM-based system ARTIPHISHELL advanced to the final of its successor, the DARPA AI Cyber Challenge. He also co-directs ASU's Laboratory of Security Engineering for Future Computing (SEFCOM).